Term Finance permanently shut down its Meta Vaults after a governance exploit enabled an estimated $8.5 million drain. The shutdown ended new deposits. Term Finance left withdrawals open. Term Labs revoked the vaults' DAO governance roles. PeckShield estimated that the attacker removed about 2,843 ETH worth $6.87 million. The attacker also removed 1.68 million USDC. The attacker swapped the USDC for roughly 1.68 million DAI. Term Finance has not confirmed the estimated $8.5 million total. Term Finance has not published its own vault-by-vault accounting. Term Finance governance documentation describes an opt-out system. Vault liquidity-provider token holders can veto queued parameter changes during a seven-day delay. A parameter change can become executable without a veto. A DeFiPrime reconstruction said an ETH Meta Vault proposal remained open for six days without a veto. The proposal's first execution actions set the delay cooldown to zero. The transaction then routed 2,841.7435 WETH through a newly added strategy to an attacker-controlled address. The Ethereum transaction occurred at 06:25 UTC on Aug. 23. A second transaction occurred about 22 minutes later. The second transaction executed five proposals across five USDC vaults. The transaction removed 1,679,639.29 USDC, according to the same analysis. Term Finance has not published a postmortem confirming how the proposer obtained authority to queue the actions. Term Finance has not confirmed why the veto and delay controls did not stop them. Yearn said Term's vault contracts use Yearn V3 architecture. Yearn said the exploit occurred through Term's custom governance wrapper. Yearn said the attack vector does not apply to standard Yearn vault setups. Yearn said standard Yearn vaults were unaffected. Term Finance said its underlying protocol and direct borrowing and lending markets had not been affected based on its investigation so far. Term Finance said it was still verifying the scope. The confirmed impact therefore remains limited to the vault product rather than every Term market. Term Finance said it was coordinating with outside security teams on remediation and recovery. Term Finance said it would explore ways to address any remaining shortfall. Term Finance did not commit to reimburse depositors. Term Finance did not provide a recovery timetable. Open withdrawals do not establish the liquidity or value available for every withdrawal because Term Finance has not confirmed the final accounting.
Term Finance Shuts Meta Vaults After $8.5M Governance Exploit
NS3Share
Term Finance closed Meta Vaults after a $8.5M governance exploit, with PeckShield tracking 2,843 ETH and 1.68M USDC drained. The attacker swapped USDC for DAI. A DeFiPrime analysis showed a six-day open proposal gap. Yearn confirmed no impact on standard vaults. Open interest in altcoins to watch remains high as Term Finance works with security teams to address the breach.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.

